HomeSecurityWhen training tools become a gateway to cloud attacks

When training tools become a gateway to cloud attacks

Hackers breach corporate cloud environments using penetration testing.

Tools designed to educate security professionals and aid in internal penetration testing are becoming unexpected entry points for cybercriminals. According to recent research from Pentera , vulnerable web applications such as DVWA, OWASP Juice Shop, Hackazon, and bWAPP are being actively exploited by attackers to compromise corporate cloud environments — even Fortune 500 organizations .

cloud

These applications are widely used for educational purposes and security audits, but they are intentionally vulnerable. When deployed in the cloud without adequate isolation or proper configuration, they become high-risk targets.

See also: LastPass: New phishing attack steals master passwords

Wrong settings, excessive privileges and open doors

Pentera's research uncovered nearly 2,000 active and exposed vulnerable applications on the public internet. Many of these were running in AWS, Google Cloud, and Microsoft Azure environments and were often associated with IAM roles that granted more privileges than required.

In several cases, applications were running with default or weak credentials, while the basic principle of “least privilege” was not respected. The result was the ability completely seize cloud resources, without much technical difficulty for attackers.

The companies affected include well-known names in the security industry, such as Cloudflare, F5, and Palo Alto Networks. All were notified by the researchers and took corrective actions.

See also: The importance of frequency in cyber risk assessments

From theory to practice: Active exploitation

The most worrying aspect of the research is that the risk is not limited to theoretical scenarios. As Pentera confirmed in a related report, these attack vectors have already been actively exploited.

When training tools become a gateway to cloud attacks

Researchers found cases where attackers installed crypto miners, webshells, and access persistence. In about 20% of DVWA cases examined, traces of malicious activity were found, with the XMRig mining Monero in the background.

Persistence mechanisms and webshells

In some compromised systems, the attackers had deployed sophisticated persistence mechanisms. A notable example was the “watchdog.sh” script, which automatically reinstalled the miner if it was deleted and re-downloaded the necessary files from GitHub.

See also: EU: Cybersecurity review and exclusion of dangerous suppliers

At the same time, PHP webshells, such as “filemanager.php”, were detected, which allowed full file control and command execution. In some cases, the webshells contained hardcoded authentication credentials and elements that may indicate the geographical origin of the operators.

What does this mean for businesses?

Pentera's findings highlight a perennial problem in cloud security: non-production systems are often treated as low priority, even though they can serve as ideal pivot points to critical infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

When training tools become a gateway to cloud attacks

The researchers recommend that enterprises maintain a complete inventory of all cloud resources, strictly isolate test environments from production, and enforce strict IAM roles. Changing default credentials, automatically expiring temporary resources, and continuous monitoring are critical steps.

In an era where the cloud is the core of corporate infrastructure, even “educational” tools can become a serious threat if not treated with the same care and security discipline.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS